Introduction
At Johnson & Johnson (J&J), our Credo drives everything that we do. This includes our commitment to cybersecurity. We value the trust our patients have placed in us regarding their health and health information. At J&J, our cybersecurity program is designed to safeguard J&J devices, data, products, services, and infrastructure.
With constantly evolving threats, J&J also recognizes the contributions that the security researcher community can bring to our cybersecurity program. As a result, we have initiated this Coordinated Vulnerability Disclosure (CVD) Program for security researchers to report new vulnerabilities that they discover in our products and infrastructure. The purpose of this program is to enhance the security of J&J devices, products, services, and infrastructure through collaboration.
Purpose, scope, expectations and rewards
At J&J, we have enacted a cybersecurity program to uphold and maintain our commitment to providing secure devices, products, and services to our patients and clients around the globe. J&J recognizes that this program can be improved through the diligent efforts of the security researcher community and their vital security research.
For vulnerabilities discovered in J&J MedTech medical devices (including Software as a Medical Device and Mobile Medical Applications), please follow the reporting procedures at productsecurity.jnj.com.
This CVD Program applies to security vulnerabilities identified in Johnson & Johnson’s infrastructure, websites, public-facing APIs, and applications. This program is not intended for product technical complaints, adverse event reports, or technical support requests. Accordingly, submissions from a security researcher regarding a vulnerability in a J&J device, product, or network may be eligible for acknowledgment through our Security Researcher Contributions page.
Eligibility of a submission for acknowledgment through the Security Researcher Contributions page will be granted at J&J’s sole discretion. However, in making this determination, J&J will consider whether the vulnerability was previously known to J&J and the submitter’s adherence to the legal principles identified below. Eligibility will not be determined until after the report has been verified, validated, and remediated.
In all instances, we expect that the security researcher will act in good faith, without malicious intent, and report discoveries in a timely fashion.
Submission process for the vulnerability reporting program
To voluntarily submit a potential vulnerability, please contact us via vulnerability_reporting@its.jnj.com and be sure to include the following information:
- A description of the exact nature of the vulnerability being reported.
- Information regarding the location of the vulnerability’s existence, as well as the infrastructure, website, public API, product, or application in which the vulnerability was uncovered.
- A detailed walkthrough of how the vulnerability was encountered and detected, including browser, operating system, versions, and any relevant configuration information.
- Any proof-of-concept code, screenshots, or supporting evidence (note: straight data dumps/exports will not be considered valid submissions).
- Your preferred contact method for secure follow-up communications.
We will acknowledge receipt of your report within 3 business days. Our security team may contact you for clarification or additional information. We will then assess and validate the report pursuant to our internal vulnerability management procedures. Where a vulnerability is confirmed, we will work on remediation according to its severity and risk profile.
We review reports to determine their eligibility for acknowledgement on our Security Researcher Contributions page. If all the criteria are met, we will notify the submitter.
Legal principles
Your participation is voluntary and does not create any expectation of employment, contractor relationship, or service-related compensation by J&J. Information voluntarily submitted to J&J will be considered non-confidential and non-proprietary. By submitting information, you agree that J&J may use the information, in whole or in part, without restriction. Submission of information does not grant you any rights or entitlement and does not create any obligation on the part of J&J.
Please be aware that this CVD Program should not be understood as permission to perform any of the following:
- Engaging in any activity disproportionate to that which is necessary to identify the existence of a vulnerability, including:
- Accessing, downloading, keeping personal information or retaining patient, proprietary, or confidential data.
- Actively trying to exploit J&J devices, products, services, or network infrastructure with malicious intent.
- Disrupting networks, services, or day-to-day operations.
- Maintaining unauthorized access beyond the scope of proving that a vulnerability exists.
- Accessing, downloading, keeping personal information or retaining patient, proprietary, or confidential data.
- Engaging in any activity that puts at risk the safety of patients, customers or operations, including, by way of example, installing malware, destroying or defacing J&J property, or denial-of-service attacks.
- Engaging in any activity that violates local law(s) or regulation(s).
Conclusion
We thank the security researcher community for contributing to a safer Internet and safer world for our patients.
Version 1.0 — [Date]. This statement will be reviewed and updated periodically.